Weaknesses of type CWE-311

312 results

Ausência de criptografia de dados sensíveis

Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.

Example

Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.

How to mitigate

Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.

CVE-2023-33833LOWIBM Security Verify Information Queue information disclosureEPSS 0.1%CVE-2026-19891MEDIUMTRENDnet TEW-WLC100 IKE Phase 1 Aggressive Mode racoon.conf missing encryptionEPSS 0.1%CVE-2024-41980LOWA vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >= V13.2 < V2506), SOA Audit (All versions >=EPSS 0.1%CVE-2026-34992HIGHMissing Encryption of Sensitive Data in antrea.io/antreaEPSS 0.1%CVE-2026-84676MEDIUMJenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller whEPSS 0.1%CVE-2025-48981HIGHAn insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and maniEPSS 0.1%CVE-2025-48862HIGHAmbiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup file is encrypted whenEPSS 0.1%CVE-2022-41627MEDIUM The physical IoT device of the AliveCor's KardiaMobile, a smartphone-based personal electrocardiogram (EKG) has no encryption for its data-EPSS 0.1%CVE-2021-22782—Missing Encryption of Sensitive Data vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.1%CVE-2026-20157HIGHCisco RoomOS Security Hardening Release - Missing Encryption VulnerabilitiesEPSS 0.1%CVE-2024-25027MEDIUMIBM Security Verify Access Container information disclosureEPSS 0.1%CVE-2023-23371MEDIUMQVPN Device ClientEPSS 0.1%CVE-2025-33020MEDIUMIBM Engineering Systems Design Rhapsody information disclosureEPSS 0.1%CVE-2025-31977MEDIUMA cryptographic weakness has been identified in the HCL BigFix Service Management (SM)EPSS 0.1%CVE-2024-38283MEDIUMMissing Encryption of Sensitive Data in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.1%CVE-2023-50126MEDIUMMissing encryption in the RFID tags of the Hozard alarm system (Alarmsysteem) v1.0 allow attackers to create a cloned tag via brief physicalEPSS 0.1%CVE-2024-7142MEDIUMOn Arista CloudVision Appliance (CVA) affected releases running on appliances that support hardware disk encryption (DCA-350E-CV only), the disk encryption might not be successfully performed. This results in the disks remaining unsecured and data on themEPSS 0.1%CVE-2024-38302MEDIUMDell Data Lakehouse, version(s) 1.0.0.0, contain(s) a Missing Encryption of Sensitive Data vulnerability in the DDAE (Starburst). A low privEPSS 0.1%CVE-2025-13053HIGHA missing encryption of sensitive data vulnerability was found in the UPS settings of ADMEPSS 0.1%CVE-2025-1243LOWField in api-go proxy not transformed before version 1.44.1EPSS 0.1%